Your data, plainly
Privacy Policy
Last updated: 13 September 2026
BookDiva is operated by Daniel Cavanagh, [South Tyneside]. This policy explains what personal data we hold, why we hold it, and what you can do about it. It applies to bookdiva.co.uk and every salon booking page hosted on it.
Who we are
BookDiva is a booking platform used by independent beauty businesses ("salons"). Each salon has its own page at a subdomain such as yoursalon.bookdiva.co.uk. In most cases the salon is the controller of its own clients' booking data, and BookDiva acts as their processor. For platform accounts (salon owner accounts and platform administration), we are the controller. Either way, the practical information below applies.
What data we hold
- Salon owner accounts: your name, email address, password (stored only as an irreversible hash), your salon's public details (name, address, logo, images, services, staff information) and your subscription status.
- Client accounts: your name, email address, hashed password, the salon you booked with, and your appointment history with that salon.
- Booking details: appointments requested, confirmed, cancelled or completed, including any notes you chose to add for the salon.
- Technical basics: server logs (IP addresses for security purposes such as rate-limiting and attack prevention), and one strictly necessary session cookie that keeps you logged in. We set no tracking, advertising or analytics cookies.
Card payments — Stripe, not us
Online payments (deposits or full payments) made through a salon's booking page are processed entirely by Stripe, the salon's own Stripe account, on Stripe's secure payment pages. We never see, receive, or store your card details — card data is entered on Stripe's systems and stays there. Questions, disputes, or problems with a payment, a deposit, or a refund should be raised with the salon and with Stripe directly; they are the payment processor for these transactions, and we have no access to the funds or the card accounts involved.
Why we hold it
- To operate your account and your bookings (contract performance).
- To send transactional emails — booking confirmations, reminders, cancellations and password resets — which are necessary for the service you asked for.
- To keep the platform secure: rate limiting, attack prevention, audit records (legitimate interests).
- To charge salon subscriptions where an account has one (contract performance).
What we never do
- We do not sell, rent, or share your personal data with advertisers or data brokers. Ever.
- We do not run tracking or analytics on you across sites.
- We do not read or use the content of booking notes, which exist for you and your salon.
How long we keep things
Account and booking data is kept while your account is active. Cancelled bookings are retained for the salon's records. Deleted accounts and their data are removed, and uploaded images are deleted from our servers when replaced or when the account is deleted.
Your rights
You can request a copy of your data, its correction, or its deletion at any time. Clients can also raise requests with their salon, who controls the booking record. To exercise any right, email [email protected] — we'll respond within 30 days as the law requires.
Security
The platform runs HTTPS everywhere, uses a firewall restricting access via Cloudflare, stores passwords only as irreversible hashes, rate-limits login attempts, verifies all payment notifications cryptographically, and re-processes every uploaded image to prevent malicious files. We take reasonable technical and organisational measures to protect your data — though no online service can promise absolute immunity from all attacks.
Contact
Questions about this policy or your data: [email protected].